Release Notes Threat Management Services zl Module ST.1.2.110427 06-2011

66
Known Issues
Release ST.1.1.100226/ST.1.1.100330
PR_42210 — The local users cannot login to the TMS zl Module web browser interface via
HTTP. Steps:
1. Open the browser and connect to TMS zl Module web browser interface via http.
2. Set the local user's name into the User name text field.
3. Set the local user's password into the Password text field.
4. Press the Login button.
The logon fails; the TMS zl Module web browser interface displays Invalid Login!. The same
local user can login successfully via HTTPS.
PR_42656 — If access policies permit, TCP Port 65105 can be discovered as open. TCP port
65105 is open for participants in a cluster to receive signature download updates from the
master. In cluster mode, it is only the master which downloads the signatures and then
synchronizes the updates with participant over the TCP connection on port 65105.
PR_42667Stateful firewall connections do not get closed promptly when their lifetime
reaches 0. From the TMS zl Module CLI, the show connections command will show
connections with a lifetime of 0 but which have not been removed. The sessions eventually
should be deleted, in most circumstances. If the number of sessions with 0 lifetime gets to
a very high level, a scheduled maintenance reboot of the TMS zl Module is required.
PR_42682 — In the web browser interface, DHCP relay settings for VLANs are not grayed
out when they are globally disabled. As a result, the DHCP relay settings can be changed for
any of the VLANs but these settings would have no effect.
PR_42951 — In the TMS zl Module CLI, show ip igmp config does not show VLAN with igmp
enabled. Steps
1. Add a vlan to a zone.
2. Enable igmp on the VLAN
3. Try to show config using: show ip igmp config
Nothing is displayed in the table. However, show ip pim does show the IGMP status for the VLAN.
PR_43431 — In the web browser interface, 'Firewall>Settings>Connection
Allocation>Connection Reservations', the TMS zl Module allows a user to add a connection
reservation for the same IP, same zone, with different connection allocations. It is unclear
which of the multiple entries will have precedence.
PR_43869When a Zone is renamed, the new Zone name does not show up in log files.
Fortunately, the order in which the Zones appear in the web browser interface
(Network>Zones>Name) can be used to determine what Zone is being referenced by the log.
The following holds true:
INTERNAL maps to the name in the 3rd row of the Zone table (3).